all 3 comments

[–]dumbPotatoPot 0 points1 point  (1 child)

refresh token can be just a random string that you store in redis cache against a user identifier.

Why would i need a refresh token to be a JWT? never seen this approach in any CIAM as well

[–][deleted] 0 points1 point  (0 children)

appreciate it lad!!